# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=68

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 69

---

## [Filebeat: send to multiple logstashes instances?](https://discuss.elastic.co/t/filebeat-send-to-multiple-logstashes-instances/319078)

<div class="topic-metadata">

**Author:** [@smm](https://discuss.elastic.co/u/smm)\
**Replies:** 1\
**Last updated:** [November 16, 2022, 3:04pm UTC](https://discuss.elastic.co/t/filebeat-send-to-multiple-logstashes-instances/319078 "2022-11-16T15:04:59Z")

</div>

Dear community, is there some kind of trick / best practice if you want in filebeat to sent to multiple logstash putput instances? I know there is some limitation in place by libbeat, but perhaps there is something you …

---

## [Filebeat version \> 7.13.X did not correctly process logs from AWS S3 Bucket](https://discuss.elastic.co/t/filebeat-version-7-13-x-did-not-correctly-process-logs-from-aws-s3-bucket/317631)

<div class="topic-metadata">

**Author:** [@anyon486](https://discuss.elastic.co/u/anyon486)\
**Replies:** 2\
**Last updated:** [November 16, 2022, 1:50pm UTC](https://discuss.elastic.co/t/filebeat-version-7-13-x-did-not-correctly-process-logs-from-aws-s3-bucket/317631 "2022-11-16T13:50:01Z")

</div>

Hi All! I work with filebeat to push logs from AWS RDS databases to a local instance of Elasticsearch. To do this, I configured AWS RDS to publish logs to specific Cloudwatch Log Group/Log Stream, and use AWS Kinesis F…

---

## [Get some log in file but not all in filebeat](https://discuss.elastic.co/t/get-some-log-in-file-but-not-all-in-filebeat/319046)

<div class="topic-metadata">

**Author:** [@devikingno](https://discuss.elastic.co/u/devikingno)\
**Replies:** 0\
**Last updated:** [November 16, 2022, 9:35am UTC](https://discuss.elastic.co/t/get-some-log-in-file-but-not-all-in-filebeat/319046 "2022-11-16T09:35:11Z")

</div>

Hello everyone, i have a problem to collect log from Filebeat to Logstash. The problem is that in the log file that I configure, I only want to get the log messages about the user's login and the other logs won't be fetc…

---

## [Filebeat can not connect to elasticsearch and kibana can not see the data](https://discuss.elastic.co/t/filebeat-can-not-connect-to-elasticsearch-and-kibana-can-not-see-the-data/318975)

<div class="topic-metadata">

**Author:** [@liuxy](https://discuss.elastic.co/u/liuxy)\
**Replies:** 0\
**Last updated:** [November 15, 2022, 3:40pm UTC](https://discuss.elastic.co/t/filebeat-can-not-connect-to-elasticsearch-and-kibana-can-not-see-the-data/318975 "2022-11-15T15:40:57Z")

</div>

Hello! I installed elasticsearch and kibana using docker on the server and filebeat on my pc. But when my filebeat tries to setup（filebeat setup）, it shows Exiting: couldn't connect to any of the configured Elasticsear…

---

## [Auditbeat Connection Refused](https://discuss.elastic.co/t/auditbeat-connection-refused/318809)

<div class="topic-metadata">

**Author:** [@learningelastic](https://discuss.elastic.co/u/learningelastic)\
**Replies:** 4\
**Last updated:** [November 15, 2022, 3:21pm UTC](https://discuss.elastic.co/t/auditbeat-connection-refused/318809 "2022-11-15T15:21:33Z")

</div>

I'm trying to learn how to set up auditbeat on the same server as my elasticsearch and kibana instance verison 8.5 which is running off of ubuntu 20.04. But when I do a systemctl start auditbeat.service, I get the error…

---

## [Unable to collect Windows logs through WinLogBeat & ElasticSearch 7.17](https://discuss.elastic.co/t/unable-to-collect-windows-logs-through-winlogbeat-elasticsearch-7-17/318897)

<div class="topic-metadata">

**Author:** [@tranceptor](https://discuss.elastic.co/u/tranceptor)\
**Replies:** 0\
**Last updated:** [November 14, 2022, 7:07pm UTC](https://discuss.elastic.co/t/unable-to-collect-windows-logs-through-winlogbeat-elasticsearch-7-17/318897 "2022-11-14T19:07:41Z")

</div>

Hello, I've just installed GrayLog + Elasticsearch and I need to collect Windows logs from a Windows machine. I installed WinLogBeat following this instructions: \[Grant access using API keys | Winlogbeat Reference \[8.5\] …

---

## [Zeek monitoring using filebeats](https://discuss.elastic.co/t/zeek-monitoring-using-filebeats/318760)

<div class="topic-metadata">

**Author:** [@PSFletchTheTek](https://discuss.elastic.co/u/PSFletchTheTek)\
**Replies:** 6\
**Last updated:** [November 15, 2022, 12:16am UTC](https://discuss.elastic.co/t/zeek-monitoring-using-filebeats/318760 "2022-11-15T00:16:24Z")

</div>

Hi, I'm using filebeats to monitor or try to monitor zeek. But I can't see any of the zeek files content in elastic, I've also enabled the system module and that burst straight into life. So I know the module config i…

---

## [Filebeat Logstash Elasticsearch Kibana](https://discuss.elastic.co/t/filebeat-logstash-elasticsearch-kibana/318905)

<div class="topic-metadata">

**Author:** [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Replies:** 1\
**Last updated:** [November 14, 2022, 10:30pm UTC](https://discuss.elastic.co/t/filebeat-logstash-elasticsearch-kibana/318905 "2022-11-14T22:30:06Z")

</div>

Hello, from a Linux machine, the syslog information is displayed via filebeat - logstash - elasticsearch in Kibana via Discover. How do I get the syslog information from another Linux server in the same index under Kib…

---

## [Several filebeat installations on a Kibana / Elasticsearch server in one log file](https://discuss.elastic.co/t/several-filebeat-installations-on-a-kibana-elasticsearch-server-in-one-log-file/318754)

<div class="topic-metadata">

**Author:** [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Replies:** 3\
**Last updated:** [November 14, 2022, 8:32pm UTC](https://discuss.elastic.co/t/several-filebeat-installations-on-a-kibana-elasticsearch-server-in-one-log-file/318754 "2022-11-14T20:32:01Z")

</div>

Hello, I have filebeat installed on a host and all syslog data is sent to Elasticsearch / Kibana. Visible via (Discover / Dashboard). Now I would like to install filebeat on another host and also transfer the syslog da…

---

## [Filebeat does not read field when it includes a new line](https://discuss.elastic.co/t/filebeat-does-not-read-field-when-it-includes-a-new-line/318886)

<div class="topic-metadata">

**Author:** [@arhodoula](https://discuss.elastic.co/u/arhodoula)\
**Replies:** 0\
**Last updated:** [November 14, 2022, 4:46pm UTC](https://discuss.elastic.co/t/filebeat-does-not-read-field-when-it-includes-a-new-line/318886 "2022-11-14T16:46:24Z")

</div>

I have the following data which filebeat cannot process due to the new line "field\_1","field\_2","field\_3","field\_4","field\_5", "921122.27872"," 34905888319","FRGG","2022-09-23","XYZ" What I need is that the second fi…

---

## [Rate limit processor not working as it should](https://discuss.elastic.co/t/rate-limit-processor-not-working-as-it-should/318882)

<div class="topic-metadata">

**Author:** [@NejcK](https://discuss.elastic.co/u/NejcK)\
**Replies:** 0\
**Last updated:** [November 14, 2022, 3:32pm UTC](https://discuss.elastic.co/t/rate-limit-processor-not-working-as-it-should/318882 "2022-11-14T15:32:37Z")

</div>

Hi. We've been using ES for a while now and saw that some apps are producing duplicate logs we'd like to limit the rate of (not drop them entirely) and have thus started using the rate\_limit processor (Rate limit the fl…

---

## [Configure index template with custom fields](https://discuss.elastic.co/t/configure-index-template-with-custom-fields/318777)

<div class="topic-metadata">

**Author:** [@Ganapati\_Basimsetti](https://discuss.elastic.co/u/Ganapati_Basimsetti)\
**Replies:** 8\
**Last updated:** [November 13, 2022, 4:00pm UTC](https://discuss.elastic.co/t/configure-index-template-with-custom-fields/318777 "2022-11-13T16:00:07Z")

</div>

Hello Team, I am trying to configure an index template using custom fields with filebeat 8.2.0. I tried various combinations and read through various topics on the forum and the docs, but I couldn't make it work. The e…

---

## [How to understand registry file in filebeat 8.3.2](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat-8-3-2/318827)

<div class="topic-metadata">

**Author:** [@bharat97](https://discuss.elastic.co/u/bharat97)\
**Replies:** 0\
**Last updated:** [November 14, 2022, 6:29am UTC](https://discuss.elastic.co/t/how-to-understand-registry-file-in-filebeat-8-3-2/318827 "2022-11-14T06:29:59Z")

</div>

Hi, Is there any way I can know, which all files are shipped by filebeat to logstash. I was reading the registry file but I am not able to understand what each record means. Here is a sample of my registry log file, can …

---

## [Load index template into Elasticsearch](https://discuss.elastic.co/t/load-index-template-into-elasticsearch/318814)

<div class="topic-metadata">

**Author:** [@sharbich](https://discuss.elastic.co/u/sharbich)\
**Replies:** 0\
**Last updated:** [November 14, 2022, 12:53am UTC](https://discuss.elastic.co/t/load-index-template-into-elasticsearch/318814 "2022-11-14T00:53:37Z")

</div>

Hello, I want to issue the following command. However, I can only access my elasticsearch via ssl. Therefore I get the following error message: root@nmanme01:~# filebeat setup -E output.logstash.enabled=false -E outp…

---

## [Exiting: index management requested but the Elasticsearch output is not configured/enabled](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/318714)

<div class="topic-metadata">

**Author:** [@mr\_ph](https://discuss.elastic.co/u/mr_ph)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 7:18am UTC](https://discuss.elastic.co/t/exiting-index-management-requested-but-the-elasticsearch-output-is-not-configured-enabled/318714 "2022-11-11T07:18:47Z")

</div>

Hi, I'm using elk stack 8.5. i want to parse the logs from beats -\> logstash -\> elasticsearch . But while i use the filebeat setup command i'm getting this error message Exiting: index management requested but the Elas…

---

## [Filebeat multiline error](https://discuss.elastic.co/t/filebeat-multiline-error/318654)

<div class="topic-metadata">

**Author:** [@arhodoula](https://discuss.elastic.co/u/arhodoula)\
**Replies:** 0\
**Last updated:** [November 10, 2022, 12:13pm UTC](https://discuss.elastic.co/t/filebeat-multiline-error/318654 "2022-11-10T12:13:51Z")

</div>

we have some database records where one field could contain a new line. Filebeat returns illegal\_argument\_exception and is dropping these events. could you please help?

---

## [Filebeats can not connect to ElasticSearch](https://discuss.elastic.co/t/filebeats-can-not-connect-to-elasticsearch/318607)

<div class="topic-metadata">

**Author:** [@Zay\_Lin\_Htun](https://discuss.elastic.co/u/Zay_Lin_Htun)\
**Replies:** 7\
**Last updated:** [November 13, 2022, 11:47pm UTC](https://discuss.elastic.co/t/filebeats-can-not-connect-to-elasticsearch/318607 "2022-11-13T23:47:45Z")

</div>

In version 8.5 of Elastic Search and Filebeats I can not ship the logs from Filebeats to Elasticsearch Here is the error log {"log.level":"info","@timestamp":"2022-11-10T04:23:19.993Z","log.logger":"add\_cloud\_metadata…

---

## [\[winlogbeat\] where log data received from Linux\_winlogbeat is stored](https://discuss.elastic.co/t/winlogbeat-where-log-data-received-from-linux-winlogbeat-is-stored/318174)

<div class="topic-metadata">

**Author:** [@shaAbe](https://discuss.elastic.co/u/shaAbe)\
**Replies:** 3\
**Last updated:** [November 13, 2022, 11:33pm UTC](https://discuss.elastic.co/t/winlogbeat-where-log-data-received-from-linux-winlogbeat-is-stored/318174 "2022-11-13T23:33:21Z")

</div>

I'm sending windows event logs to elasticsearch using winlogbeat. And I'm using kibana to display the event log data received by elasticsearch. So I have one question. Where in the Linux directory is elasticsearch sto…

---

## [Cannot index event publisher - new line](https://discuss.elastic.co/t/cannot-index-event-publisher-new-line/318751)

<div class="topic-metadata">

**Author:** [@arhodoula](https://discuss.elastic.co/u/arhodoula)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 3:25pm UTC](https://discuss.elastic.co/t/cannot-index-event-publisher-new-line/318751 "2022-11-11T15:25:04Z")

</div>

I am getting an illegal\_argument\_exception in filebeat. I found out it is because of the "reason": """Illegal unquoted character ((CTRL-CHAR, code 13)): has to be escaped using backslash to be included in string value …

---

## [Suricata SIEM](https://discuss.elastic.co/t/suricata-siem/318733)

<div class="topic-metadata">

**Author:** [@Ryhal\_Kumar](https://discuss.elastic.co/u/Ryhal_Kumar)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 11:15am UTC](https://discuss.elastic.co/t/suricata-siem/318733 "2022-11-11T11:15:32Z")

</div>

I am running a suricata siem with suricata,elasticsearch,kibana and filebeat. But there are few issues, while the dashboard is running it is fine but when I run a ddos attack using kali it stops working and shows alert o…

---

## [Use Filebeat in MacOS M1 to ship extracted win evtx file to docker ELK](https://discuss.elastic.co/t/use-filebeat-in-macos-m1-to-ship-extracted-win-evtx-file-to-docker-elk/318723)

<div class="topic-metadata">

**Author:** [@Roger\_Huang](https://discuss.elastic.co/u/Roger_Huang)\
**Replies:** 0\
**Last updated:** [November 11, 2022, 10:19am UTC](https://discuss.elastic.co/t/use-filebeat-in-macos-m1-to-ship-extracted-win-evtx-file-to-docker-elk/318723 "2022-11-11T10:19:09Z")

</div>

Hi all, I am new to ELK. I know this may sounds weird. But I am doing some POC and testing by extracting a Sysmon EVTX from a windows server. The workstation I am using a Mac M1. I installed filebeat in Mac and wanted …

---

## [Can filebeat's o365 module fetch windows defender logs](https://discuss.elastic.co/t/can-filebeats-o365-module-fetch-windows-defender-logs/317575)

<div class="topic-metadata">

**Author:** [@sriramb12](https://discuss.elastic.co/u/sriramb12)\
**Replies:** 2\
**Last updated:** [November 10, 2022, 8:35pm UTC](https://discuss.elastic.co/t/can-filebeats-o365-module-fetch-windows-defender-logs/317575 "2022-11-10T20:35:50Z")

</div>

Hello Team I am looking for some insights on fetching windwos defender logs via filebeat (o365 module) Currently the o365 config (yml) lists these: List of content-types to fetch. By default all known content-types # …

---

## [How to install two Winlogbeat instances in same machine](https://discuss.elastic.co/t/how-to-install-two-winlogbeat-instances-in-same-machine/318674)

<div class="topic-metadata">

**Author:** [@hiruni.insyncit.net](https://discuss.elastic.co/u/hiruni.insyncit.net)\
**Replies:** 2\
**Last updated:** [November 10, 2022, 5:53pm UTC](https://discuss.elastic.co/t/how-to-install-two-winlogbeat-instances-in-same-machine/318674 "2022-11-10T17:53:36Z")

</div>

I'm using Elasticsearch 8.1 version and I want send Winlogbeat data to different ES clusters. I want to know how I can do it...?

---

## [Winlogbeat 8.0.0 parsing with module](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812)

<div class="topic-metadata">

**Author:** [@vitkon](https://discuss.elastic.co/u/vitkon)\
**Replies:** 9\
**Last updated:** [November 10, 2022, 2:25pm UTC](https://discuss.elastic.co/t/winlogbeat-8-0-0-parsing-with-module/317812 "2022-11-10T14:25:49Z")

</div>

Hello everyone I have an ELK 8.0.0 series. I am testing the build of windows logs using winlogbeat 8.0.0. As I understand from the elastic documentation, the parsing of raw windows events will be by means of Security, P…

---

## [Fortinet Integration not parsing all data](https://discuss.elastic.co/t/fortinet-integration-not-parsing-all-data/316849)

<div class="topic-metadata">

**Author:** [@sirineb](https://discuss.elastic.co/u/sirineb)\
**Replies:** 3\
**Last updated:** [November 10, 2022, 1:54pm UTC](https://discuss.elastic.co/t/fortinet-integration-not-parsing-all-data/316849 "2022-11-10T13:54:55Z")

</div>

Hi, I noticed a problem with the Fortinet integration. I have an Elastic Agent 8.3 installed on a virtual machine. The policy for this Agent is composed of system and the fortinet integration. Our fortianalyzer is sendi…

---

## [Filebeat @timestamp not overwritten parsing error](https://discuss.elastic.co/t/filebeat-timestamp-not-overwritten-parsing-error/318466)

<div class="topic-metadata">

**Author:** [@pi314](https://discuss.elastic.co/u/pi314)\
**Replies:** 2\
**Last updated:** [November 10, 2022, 12:36pm UTC](https://discuss.elastic.co/t/filebeat-timestamp-not-overwritten-parsing-error/318466 "2022-11-10T12:36:09Z")

</div>

Hello, i see this warning in filebeat logs: 2022-11-08T15:24:21.094Z ERROR \[jsonhelper\] jsontransform/jsonhelper.go:62 JSON: Won't overwrite @timestamp because of parsing error: parsing time "2022-11-07T14…

---

## [Filebeat -\> Exiting: failed reading meta file: unexpected end of JSON input](https://discuss.elastic.co/t/filebeat-exiting-failed-reading-meta-file-unexpected-end-of-json-input/318535)

<div class="topic-metadata">

**Author:** [@Dissonance](https://discuss.elastic.co/u/Dissonance)\
**Replies:** 3\
**Last updated:** [November 10, 2022, 10:21am UTC](https://discuss.elastic.co/t/filebeat-exiting-failed-reading-meta-file-unexpected-end-of-json-input/318535 "2022-11-10T10:21:32Z")

</div>

Good afternoon, OS: Ubuntu 22.04 I tried Filebeat (version 8.5 and 7.17.1). Both versions cannot be started with the error: {"log.level":"error","@timestamp":"2022-11-09T11:28:21.598Z","log.origin":{"file.name":"insta…

---

## [Where to apply the JSON settings in Filebeat input section](https://discuss.elastic.co/t/where-to-apply-the-json-settings-in-filebeat-input-section/318289)

<div class="topic-metadata">

**Author:** [@yasar](https://discuss.elastic.co/u/yasar)\
**Replies:** 4\
**Last updated:** [November 10, 2022, 10:03am UTC](https://discuss.elastic.co/t/where-to-apply-the-json-settings-in-filebeat-input-section/318289 "2022-11-10T10:03:37Z")

</div>

Hi team, We would like to separate to view the JSON field and message field in kibana logs and that we found out the JSON settings below. json.keys\_under\_root: true json.add\_error\_key: true json.message\_key: log Coul…

---

## [How to Monitor the process using metricbeat](https://discuss.elastic.co/t/how-to-monitor-the-process-using-metricbeat/318525)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 5\
**Last updated:** [November 10, 2022, 6:32am UTC](https://discuss.elastic.co/t/how-to-monitor-the-process-using-metricbeat/318525 "2022-11-10T06:32:55Z")

</div>

How to Monitor the process using metricbeat in windows. Should we include the process details in the configuration yml of metricbeat? currently without mentioning any process details in config file its only showing proc…

---

## [How to set https in beats agents configuration](https://discuss.elastic.co/t/how-to-set-https-in-beats-agents-configuration/318527)

<div class="topic-metadata">

**Author:** [@jisha](https://discuss.elastic.co/u/jisha)\
**Replies:** 2\
**Last updated:** [November 10, 2022, 5:32am UTC](https://discuss.elastic.co/t/how-to-set-https-in-beats-agents-configuration/318527 "2022-11-10T05:32:26Z")

</div>

how to set https in beats agents configuration ? i am using 7.17.3 v of elk. output is through logstash.

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=67)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=69)
